[Openswan Users] mac os x 10.5.6 is not working when it has a public IP but works if behind a NAT

Kailesh Mussai kmussa at cs.mcgill.ca
Wed Apr 22 16:38:40 EDT 2009


Hello all,

This is a IPsec/L2TP setup.

The same setup works for older Mac OS X for both public IP and for NAT,
also works with Windows XP and linux.  I am having issues with the newest
Mac OS X 10.5.  I attached the logs and if I disable nat_traversal, then
I able to connect.

I cannot tell if it's Mac OS X bug or if it is my setup missing
something.

Any help on this would be much appreciated. 

Openswan version:
Linux Openswan U2.4.12/K2.6.18-6-686 (netkey)

xl2tpd version:  xl2tpd-1.2.4

My ipsec.conf:
############################################################################################
config setup
        nat_traversal=yes
        virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!10.0.11.0/24
        nhelpers=0
        plutodebug=none
        plutostderrlog=/var/log/pluto.log

conn roadwarrior-l2tp
        leftprotoport=17/1701
        rightprotoport=17/%any
        also=roadwarrior

conn roadwarrior-l2tp-updatedwin
        leftprotoport=17/1701
        rightprotoport=17/1701
        also=roadwarrior

conn roadwarrior
        authby=secret
        pfs=no
        keyingtries=3
        rekey=no
        left=132.206.54.11
        right=%any
        rightsubnet=vhost:%priv,%no
        auto=add
############################################################################################

Regards,
Kailesh 


More information about the Users mailing list